Home About Services Support Contact Projects Blog Podcast
216.785.2700 support@microadv.com Login

Your Remote IT Tool Could Be an Attacker’s Back Door: Microsoft Warns of New RMM Phishing Attacks

What Happened?

Microsoft Defender Experts observed phishing campaigns beginning in July 2026 that targeted organizations across multiple industries.

The phishing messages used familiar business scenarios to convince users to download and execute a file.

Microsoft observed lures involving:

  • Meeting invitations

  • PDF-related documents

  • Software-update notifications

  • Other business-themed content

But the downloaded program wasn't traditional malware.

It was a legitimate, digitally signed version of MSP360 Remote Monitoring and Management software disguised under deceptive filenames.

When the employee approved the installation—including the Windows User Account Control prompt—the RMM agent installed its services and established persistent remote access.

At that point, the attacker effectively had their own IT-management tool installed on the computer.

And they didn't stop there.

Attackers Installed a Second Remote-Access Tool

After establishing access through MSP360, Microsoft observed attackers using the RMM platform to execute PowerShell and silently install ConnectWise ScreenConnect.

That created a second remote-access channel.

Microsoft specifically noted that attackers were not exploiting a ScreenConnect vulnerability in this campaign.

Instead, they were using legitimate ScreenConnect software as another way to maintain control over the compromised computer.

Think of it like an attacker getting into a building and then installing a second door in case the first one gets locked.

Removing one remote-access tool might not remove the attacker.

Why Would Attackers Use Legitimate IT Software?

Because it helps them blend in.

Remote monitoring and management software is commonly used by:

  • Managed service providers

  • Internal IT departments

  • Software vendors

  • Help desks

  • Equipment vendors

  • Remote technicians

These applications legitimately perform powerful administrative functions.

Depending on the product and permissions, an RMM platform may allow a technician to:

  • Remotely control a computer

  • Execute PowerShell

  • Run scripts

  • Install applications

  • Transfer files

  • Collect system information

  • Restart computers

  • Manage services

  • Troubleshoot systems

Those capabilities are incredibly useful for legitimate IT support.

They're also incredibly useful to an attacker.

This Creates a Difficult Security Problem

Traditional security thinking often focuses on identifying malicious programs.

But what happens when the attacker's software is legitimate?

MSP360 is legitimate.

ScreenConnect is legitimate.

PowerShell is legitimate.

Windows services are legitimate.

An attacker abusing these technologies may therefore appear, at least initially, similar to an IT administrator performing normal maintenance.

Microsoft's investigation demonstrates why modern endpoint security needs to evaluate behavior, not simply whether an application is known malware.

What Happened After Attackers Got Access?

Once the remote-management infrastructure was established, Microsoft observed additional post-compromise activity.

Attackers used their remote access for information collection and attempted credential-access activity.

Microsoft Defender detected behaviors including:

  • Suspicious remote-management activity

  • Uncommon remote-access software

  • Suspicious services

  • Persistence mechanisms

  • Potential theft of browser passwords and sensitive information

The attackers were no longer trying to convince an employee to click something.

They were already inside the computer.

Why Small and Midsize Businesses Should Pay Attention

RMM software is particularly common in small and midsize businesses because many organizations outsource some or all of their IT operations.

That is not inherently a security problem.

Professional remote management allows an MSP to monitor computers, install updates, troubleshoot problems, deploy software, and respond quickly when something goes wrong.

The problem arises when businesses don't know which remote-management tools should be installed.

Over several years, a company may accumulate remote-access software from:

  • Its current IT provider

  • A previous IT company

  • Printer vendors

  • Accounting software vendors

  • Line-of-business software companies

  • Security vendors

  • Employees who installed remote-support applications themselves

You could potentially find several remote-access agents on the same computer.

And nobody remembers why they're there.

That creates unnecessary risk.

Your Business Should Have an Approved RMM List

Every organization should be able to answer one simple question:

What software is authorized to remotely control our computers?

If the answer is unclear, that should become an IT-security priority.

Your IT provider should maintain an inventory of approved remote-management applications.

Anything outside that list should be investigated.

For example, if your organization normally uses one RMM platform and suddenly another remote-management agent appears on 15 computers, that should generate attention.

It might be legitimate.

Or it might be exactly the type of activity Microsoft recently observed.

What Businesses Should Do Now

1. Inventory Remote-Access Software

Determine which remote-management applications exist across company computers and servers.

Common examples include:

  • ConnectWise ScreenConnect

  • MSP360

  • Splashtop

  • TeamViewer

  • AnyDesk

  • LogMeIn

  • BeyondTrust

  • Various MSP RMM agents

  • Vendor-specific remote-support software

Finding an application doesn't automatically mean it is malicious.

The important question is:

Who installed it, who controls it, and is it still required?

2. Remove Old RMM Agents

Changing IT providers should include removing the previous provider's remote-management software.

Old agents should not remain installed indefinitely.

The same principle applies to vendors.

If a software company needed temporary remote access six months ago, determine whether that software still needs to exist today.

Every unnecessary remote-access application creates another potential administrative pathway into your environment.

3. Restrict Software Installation

In Microsoft's observed attack, the user had to execute the disguised installer and approve elevation through Windows User Account Control.

That makes local administrator permissions important.

Employees should generally not have administrative privileges unless their job genuinely requires them.

Removing unnecessary local administrator rights can make it substantially harder for a phishing attack to become a full remote-access compromise.

4. Monitor for Unexpected RMM Software

Endpoint detection and response platforms should be configured to identify unusual remote-management activity.

Microsoft Defender for Endpoint, for example, includes detections for suspicious and uncommon remote-access software and behaviors associated with the campaign Microsoft investigated.

Businesses should not rely solely on traditional antivirus signatures.

The question isn't always:

"Is this application malicious?"

Sometimes the better question is:

"Should this application be running on this computer?"

5. Require MFA for Remote-Management Platforms

Your legitimate RMM platform is powerful.

Protect it accordingly.

Technicians should use individual accounts protected with multifactor authentication whenever the platform supports it.

Avoid shared technician accounts whenever possible.

That provides both stronger authentication and better auditing.

If suspicious activity occurs, you want to know exactly which account initiated the remote session.

6. Train Employees About Fake Software Updates

Employees should be suspicious of unexpected emails asking them to install:

  • Software updates

  • Meeting applications

  • Remote-support software

  • PDF readers

  • Browser updates

  • Security applications

Software updates should ideally be managed centrally by IT rather than installed from links employees receive through email.

A simple rule can prevent many attacks:

If an email tells you to install software, contact IT first.

7. Don't Assume Removing One Tool Ends the Incident

This attack demonstrates another important incident-response lesson.

If unauthorized RMM software is discovered, simply uninstalling it may not be enough.

Microsoft observed attackers installing multiple remote-access mechanisms.

An investigation should determine:

  • How the software was installed

  • When it appeared

  • Which user executed it

  • What commands were run

  • Whether another RMM agent was installed

  • Whether credentials were accessed

  • Whether additional computers were contacted

  • Whether persistence mechanisms were created

  • Whether accounts need passwords or tokens reset

Finding unauthorized remote-access software should be treated as a potential security incident—not simply unwanted software.

The Bigger Cybersecurity Lesson

For years, businesses were taught that cybersecurity meant preventing malicious programs from entering the network.

That model is becoming outdated.

Modern attackers increasingly abuse legitimate technology.

Remote-management applications.

PowerShell.

Cloud services.

Microsoft 365.

OAuth applications.

Remote desktop tools.

Attackers don't necessarily need to create sophisticated malware when trusted administrative tools already provide the capabilities they need.

That's why modern cybersecurity increasingly depends on understanding what is normal for your environment.

If your company uses one approved RMM platform, seeing another one suddenly appear should be unusual.

If employees normally receive software through centralized IT management, someone manually downloading a remote-support installer should be unusual.

Security tools—and the people monitoring them—need enough visibility to recognize those differences.

How MicroAdvantage Can Help

At MicroAdvantage, remote management is an important part of how we support and protect our clients—but remote access also needs to be carefully controlled.

We help businesses understand exactly who can access their systems, what tools provide that access, and how those tools are protected.

A MicroAdvantage IT and cybersecurity review can include:

  • RMM and remote-access software auditing

  • Removal of unauthorized or outdated remote tools

  • Microsoft Defender for Endpoint

  • Endpoint detection and response

  • Windows patch management

  • Local administrator reviews

  • Microsoft 365 security

  • Multifactor authentication

  • Conditional Access

  • Firewall and network security

  • Email and phishing protection

  • Backup and disaster recovery

  • User security awareness

Cybercriminals are increasingly trying to make their activity look like normal IT administration.

That means businesses need more than antivirus.

They need visibility.

If you're not sure what software can remotely access your company's computers—or who controls it—MicroAdvantage can help you find out and make sure that access is properly secured.




Sources

Microsoft Security Blog — “Phishing Abuses RMM Tools for Persistent Access,” published September 29, 2026. Microsoft's investigation provides the primary technical details about the MSP360 phishing campaign, ScreenConnect deployment, persistence, credential-access activity, and recommended defenses.

CISA — Cybersecurity Alerts & Advisories. CISA continues to highlight active exploitation and the importance of rapidly addressing vulnerabilities and threats affecting internet-facing and administrative infrastructure.

MicroAdvantage Takeaway

Know what can remotely access your computers. Know who controls it. Secure it like an administrator account.


« Back to the blog